Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-85978: Akana API Platform Policy Manager can run attacker code

CVE-2026-85978 · published 1 month ago
Summary

The Policy Manager console in Akana API Platform can be accessed without a login, letting an attacker send a specially crafted request that runs their own code on the server. This means the attacker could take control of the system hosting the API platform. Apply the latest security update from Akana and limit network access to the console to trusted users.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
perforce akana < 2024.1.6
<= 2024.1.5
Original advisory text
An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet...
An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to bypass authentication and reach an endpoint that evaluates attacker-supplied script code without sandboxing, resulting in arbitrary code execution. Exploitation requires no authentication or user interaction.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
10.0 Critical
Exploitation
1% chance of attack within 30 days
Type
CWE-41Improper Resolution of Path Equivalence
CWE-94Code Injection
CWE-863Incorrect Authorization
Timeline
Published9 Sep 2026
Updated7 Oct 2026
First seen9 Sep 2026
Sources
CVE-2026-85978 · MITRE
Track software like this
Free during beta